Active Honey Files for Ransomware Encryption Mitigation

Ioannis Stamelos, George Hatzivasilis, Sotiris Ioannidis · 2024

Ransomware has emerged as one of the most damaging cyber-threats, causing financial losses and data breaches across various sectors. Since detection methods are constantly improved, the ransomware itself becomes equally better in avoiding detection. This paper proposes a mitigation solution for ransomware based on HoneyFiles. The idea is that the user deploys decoy files, focusing on folders that popular ransomware is targeting. Normally, no one interacts with those files. When a process tries to open, move, delete, or rename them, the mechanism identifies the process as malicious and kills it, notifying the user accordingly. The goal is to stop the encryption functionality of ransowmare. The solution was tested on Windows against 23 open-source ransomware, mitigating around 95% of them. Potentially, this approach could also protect a system against other attacks, like data breaches. Moreover, HoneyFIles are applied in the EU-funded project SecOPERA for the protection modern IoT and ICT infrastructures.

Read the paper · More papers on PaperTik